16d756449SSean Bruno /*- 2910938f0SSean Bruno * Copyright (c) 2013-16, Stacey D. Son 36d756449SSean Bruno * All rights reserved. 46d756449SSean Bruno * 56d756449SSean Bruno * Redistribution and use in source and binary forms, with or without 66d756449SSean Bruno * modification, are permitted provided that the following conditions 76d756449SSean Bruno * are met: 86d756449SSean Bruno * 1. Redistributions of source code must retain the above copyright 96d756449SSean Bruno * notice, this list of conditions and the following disclaimer. 106d756449SSean Bruno * 2. Redistributions in binary form must reproduce the above copyright 116d756449SSean Bruno * notice, this list of conditions and the following disclaimer in the 126d756449SSean Bruno * documentation and/or other materials provided with the distribution. 136d756449SSean Bruno * 146d756449SSean Bruno * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 156d756449SSean Bruno * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 166d756449SSean Bruno * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 176d756449SSean Bruno * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 186d756449SSean Bruno * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 196d756449SSean Bruno * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 206d756449SSean Bruno * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 216d756449SSean Bruno * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 226d756449SSean Bruno * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 236d756449SSean Bruno * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 246d756449SSean Bruno * SUCH DAMAGE. 256d756449SSean Bruno */ 266d756449SSean Bruno 276d756449SSean Bruno #include <sys/cdefs.h> 286d756449SSean Bruno __FBSDID("$FreeBSD$"); 296d756449SSean Bruno 306d756449SSean Bruno #include <sys/param.h> 316d756449SSean Bruno #include <sys/ctype.h> 326d756449SSean Bruno #include <sys/exec.h> 336d756449SSean Bruno #include <sys/imgact.h> 346d756449SSean Bruno #include <sys/imgact_binmisc.h> 356d756449SSean Bruno #include <sys/kernel.h> 366d756449SSean Bruno #include <sys/lock.h> 376d756449SSean Bruno #include <sys/malloc.h> 386d756449SSean Bruno #include <sys/mutex.h> 39df69035dSKyle Evans #include <sys/sbuf.h> 406d756449SSean Bruno #include <sys/sysctl.h> 415f98711dSSean Bruno #include <sys/sx.h> 425f98711dSSean Bruno 435f98711dSSean Bruno #include <machine/atomic.h> 446d756449SSean Bruno 456d756449SSean Bruno /** 466d756449SSean Bruno * Miscellaneous binary interpreter image activator. 476d756449SSean Bruno * 486d756449SSean Bruno * If the given target executable's header matches 'xbe_magic' field in the 496d756449SSean Bruno * 'interpreter_list' then it will use the user-level interpreter specified in 506d756449SSean Bruno * the 'xbe_interpreter' field to execute the binary. The 'xbe_magic' field may 516d756449SSean Bruno * be adjusted to a given offset using the value in the 'xbe_moffset' field 526d756449SSean Bruno * and bits of the header may be masked using the 'xbe_mask' field. The 536d756449SSean Bruno * 'interpreter_list' entries are managed using sysctl(3) as described in the 546d756449SSean Bruno * <sys/imgact_binmisc.h> file. 556d756449SSean Bruno */ 566d756449SSean Bruno 576d756449SSean Bruno /* 586d756449SSean Bruno * Node of the interpreter list. 596d756449SSean Bruno */ 606d756449SSean Bruno typedef struct imgact_binmisc_entry { 61ecb4fdf9SKyle Evans SLIST_ENTRY(imgact_binmisc_entry) link; 626d756449SSean Bruno char *ibe_name; 636d756449SSean Bruno uint8_t *ibe_magic; 646d756449SSean Bruno uint8_t *ibe_mask; 656d756449SSean Bruno uint8_t *ibe_interpreter; 66*1024ef27SKyle Evans ssize_t ibe_interp_offset; 676d756449SSean Bruno uint32_t ibe_interp_argcnt; 686d756449SSean Bruno uint32_t ibe_interp_length; 69*1024ef27SKyle Evans uint32_t ibe_argv0_cnt; 706d756449SSean Bruno uint32_t ibe_flags; 71ecb4fdf9SKyle Evans uint32_t ibe_moffset; 72ecb4fdf9SKyle Evans uint32_t ibe_msize; 736d756449SSean Bruno } imgact_binmisc_entry_t; 746d756449SSean Bruno 756d756449SSean Bruno /* 766d756449SSean Bruno * sysctl() commands. 776d756449SSean Bruno */ 786d756449SSean Bruno #define IBC_ADD 1 /* Add given entry. */ 796d756449SSean Bruno #define IBC_REMOVE 2 /* Remove entry for a given name. */ 806d756449SSean Bruno #define IBC_DISABLE 3 /* Disable entry for a given name. */ 816d756449SSean Bruno #define IBC_ENABLE 4 /* Enable entry for a given name. */ 826d756449SSean Bruno #define IBC_LOOKUP 5 /* Lookup and return entry for given name. */ 836d756449SSean Bruno #define IBC_LIST 6 /* Get a snapshot of the interpretor list. */ 846d756449SSean Bruno 856d756449SSean Bruno /* 866d756449SSean Bruno * Interpreter string macros. 876d756449SSean Bruno * 886d756449SSean Bruno * They all start with '#' followed by a single letter: 896d756449SSean Bruno */ 906d756449SSean Bruno #define ISM_POUND '#' /* "##" is the escape sequence for single #. */ 916d756449SSean Bruno #define ISM_OLD_ARGV0 'a' /* "#a" is replaced with the old argv0. */ 926d756449SSean Bruno 936d756449SSean Bruno MALLOC_DEFINE(M_BINMISC, KMOD_NAME, "misc binary image activator"); 946d756449SSean Bruno 956d756449SSean Bruno /* The interpreter list. */ 966d756449SSean Bruno static SLIST_HEAD(, imgact_binmisc_entry) interpreter_list = 976d756449SSean Bruno SLIST_HEAD_INITIALIZER(interpreter_list); 986d756449SSean Bruno 99df69035dSKyle Evans static int interp_list_entry_count; 100280b7169SSean Bruno 1015f98711dSSean Bruno static struct sx interp_list_sx; 1026d756449SSean Bruno 1032192cd12SKyle Evans #define INTERP_LIST_WLOCK() sx_xlock(&interp_list_sx) 1042192cd12SKyle Evans #define INTERP_LIST_RLOCK() sx_slock(&interp_list_sx) 1052192cd12SKyle Evans #define INTERP_LIST_WUNLOCK() sx_xunlock(&interp_list_sx) 1062192cd12SKyle Evans #define INTERP_LIST_RUNLOCK() sx_sunlock(&interp_list_sx) 1072192cd12SKyle Evans 1082192cd12SKyle Evans #define INTERP_LIST_LOCK_INIT() sx_init(&interp_list_sx, KMOD_NAME) 1092192cd12SKyle Evans #define INTERP_LIST_LOCK_DESTROY() sx_destroy(&interp_list_sx) 1102192cd12SKyle Evans 1112192cd12SKyle Evans #define INTERP_LIST_ASSERT_LOCKED() sx_assert(&interp_list_sx, SA_LOCKED) 1122192cd12SKyle Evans 1136d756449SSean Bruno /* 1146d756449SSean Bruno * Populate the entry with the information about the interpreter. 1156d756449SSean Bruno */ 1166d756449SSean Bruno static void 1176d756449SSean Bruno imgact_binmisc_populate_interp(char *str, imgact_binmisc_entry_t *ibe) 1186d756449SSean Bruno { 1196d756449SSean Bruno uint32_t len = 0, argc = 1; 1206d756449SSean Bruno char t[IBE_INTERP_LEN_MAX]; 1216d756449SSean Bruno char *sp, *tp; 1226d756449SSean Bruno 1235f98711dSSean Bruno memset(t, 0, sizeof(t)); 1246d756449SSean Bruno 1256d756449SSean Bruno /* 1266d756449SSean Bruno * Normalize interpreter string. Replace white space between args with 1276d756449SSean Bruno * single space. 1286d756449SSean Bruno */ 1296d756449SSean Bruno sp = str; tp = t; 1306d756449SSean Bruno while (*sp != '\0') { 1316d756449SSean Bruno if (*sp == ' ' || *sp == '\t') { 13226af6115SEd Maste if (++len >= IBE_INTERP_LEN_MAX) 1336d756449SSean Bruno break; 1346d756449SSean Bruno *tp++ = ' '; 1356d756449SSean Bruno argc++; 1366d756449SSean Bruno while (*sp == ' ' || *sp == '\t') 1376d756449SSean Bruno sp++; 1386d756449SSean Bruno continue; 1396d756449SSean Bruno } else { 1406d756449SSean Bruno *tp++ = *sp++; 1416d756449SSean Bruno len++; 1426d756449SSean Bruno } 1436d756449SSean Bruno } 1446d756449SSean Bruno *tp = '\0'; 1456d756449SSean Bruno len++; 1466d756449SSean Bruno 1476d756449SSean Bruno ibe->ibe_interpreter = malloc(len, M_BINMISC, M_WAITOK|M_ZERO); 1486d756449SSean Bruno 1496d756449SSean Bruno /* Populate all the ibe fields for the interpreter. */ 1506d756449SSean Bruno memcpy(ibe->ibe_interpreter, t, len); 1516d756449SSean Bruno ibe->ibe_interp_argcnt = argc; 1526d756449SSean Bruno ibe->ibe_interp_length = len; 1536d756449SSean Bruno } 1546d756449SSean Bruno 1556d756449SSean Bruno /* 1566d756449SSean Bruno * Allocate memory and populate a new entry for the interpreter table. 1576d756449SSean Bruno */ 1586d756449SSean Bruno static imgact_binmisc_entry_t * 159*1024ef27SKyle Evans imgact_binmisc_new_entry(ximgact_binmisc_entry_t *xbe, ssize_t interp_offset, 160*1024ef27SKyle Evans int argv0_cnt) 1616d756449SSean Bruno { 1626d756449SSean Bruno imgact_binmisc_entry_t *ibe = NULL; 1636d756449SSean Bruno size_t namesz = min(strlen(xbe->xbe_name) + 1, IBE_NAME_MAX); 1646d756449SSean Bruno 1656d756449SSean Bruno ibe = malloc(sizeof(*ibe), M_BINMISC, M_WAITOK|M_ZERO); 1666d756449SSean Bruno 1676d756449SSean Bruno ibe->ibe_name = malloc(namesz, M_BINMISC, M_WAITOK|M_ZERO); 1686d756449SSean Bruno strlcpy(ibe->ibe_name, xbe->xbe_name, namesz); 1696d756449SSean Bruno 1706d756449SSean Bruno imgact_binmisc_populate_interp(xbe->xbe_interpreter, ibe); 1716d756449SSean Bruno 1726d756449SSean Bruno ibe->ibe_magic = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO); 1736d756449SSean Bruno memcpy(ibe->ibe_magic, xbe->xbe_magic, xbe->xbe_msize); 1746d756449SSean Bruno 1756d756449SSean Bruno ibe->ibe_mask = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO); 1766d756449SSean Bruno memcpy(ibe->ibe_mask, xbe->xbe_mask, xbe->xbe_msize); 1776d756449SSean Bruno 1786d756449SSean Bruno ibe->ibe_moffset = xbe->xbe_moffset; 1796d756449SSean Bruno ibe->ibe_msize = xbe->xbe_msize; 1806d756449SSean Bruno ibe->ibe_flags = xbe->xbe_flags; 181*1024ef27SKyle Evans ibe->ibe_interp_offset = interp_offset; 182*1024ef27SKyle Evans ibe->ibe_argv0_cnt = argv0_cnt; 1836d756449SSean Bruno return (ibe); 1846d756449SSean Bruno } 1856d756449SSean Bruno 1866d756449SSean Bruno /* 1876d756449SSean Bruno * Free the allocated memory for a given list item. 1886d756449SSean Bruno */ 1896d756449SSean Bruno static void 1906d756449SSean Bruno imgact_binmisc_destroy_entry(imgact_binmisc_entry_t *ibe) 1916d756449SSean Bruno { 1926d756449SSean Bruno if (!ibe) 1936d756449SSean Bruno return; 194b888dae4SSean Bruno if (ibe->ibe_magic) 1956d756449SSean Bruno free(ibe->ibe_magic, M_BINMISC); 1966d756449SSean Bruno if (ibe->ibe_mask) 1976d756449SSean Bruno free(ibe->ibe_mask, M_BINMISC); 1986d756449SSean Bruno if (ibe->ibe_interpreter) 1996d756449SSean Bruno free(ibe->ibe_interpreter, M_BINMISC); 2006d756449SSean Bruno if (ibe->ibe_name) 2016d756449SSean Bruno free(ibe->ibe_name, M_BINMISC); 2026d756449SSean Bruno if (ibe) 2036d756449SSean Bruno free(ibe, M_BINMISC); 2046d756449SSean Bruno } 2056d756449SSean Bruno 2066d756449SSean Bruno /* 2076d756449SSean Bruno * Find the interpreter in the list by the given name. Return NULL if not 2086d756449SSean Bruno * found. 2096d756449SSean Bruno */ 2106d756449SSean Bruno static imgact_binmisc_entry_t * 2116d756449SSean Bruno imgact_binmisc_find_entry(char *name) 2126d756449SSean Bruno { 2136d756449SSean Bruno imgact_binmisc_entry_t *ibe; 2146d756449SSean Bruno 2152192cd12SKyle Evans INTERP_LIST_ASSERT_LOCKED(); 2166d756449SSean Bruno 2176d756449SSean Bruno SLIST_FOREACH(ibe, &interpreter_list, link) { 2186d756449SSean Bruno if (strncmp(name, ibe->ibe_name, IBE_NAME_MAX) == 0) 2196d756449SSean Bruno return (ibe); 2206d756449SSean Bruno } 2216d756449SSean Bruno 2226d756449SSean Bruno return (NULL); 2236d756449SSean Bruno } 2246d756449SSean Bruno 2256d756449SSean Bruno /* 2266d756449SSean Bruno * Add the given interpreter if it doesn't already exist. Return EEXIST 2276d756449SSean Bruno * if the name already exist in the interpreter list. 2286d756449SSean Bruno */ 2296d756449SSean Bruno static int 2306d756449SSean Bruno imgact_binmisc_add_entry(ximgact_binmisc_entry_t *xbe) 2316d756449SSean Bruno { 2326d756449SSean Bruno imgact_binmisc_entry_t *ibe; 2336d756449SSean Bruno char *p; 234*1024ef27SKyle Evans ssize_t interp_offset; 235*1024ef27SKyle Evans int argv0_cnt, cnt; 2366d756449SSean Bruno 2376d756449SSean Bruno if (xbe->xbe_msize > IBE_MAGIC_MAX) 2386d756449SSean Bruno return (EINVAL); 2396d756449SSean Bruno 240910938f0SSean Bruno for(cnt = 0, p = xbe->xbe_name; *p != 0; cnt++, p++) 241910938f0SSean Bruno if (cnt >= IBE_NAME_MAX || !isascii((int)*p)) 2426d756449SSean Bruno return (EINVAL); 2436d756449SSean Bruno 244910938f0SSean Bruno for(cnt = 0, p = xbe->xbe_interpreter; *p != 0; cnt++, p++) 245910938f0SSean Bruno if (cnt >= IBE_INTERP_LEN_MAX || !isascii((int)*p)) 2466d756449SSean Bruno return (EINVAL); 2476d756449SSean Bruno 2486d756449SSean Bruno /* Make sure we don't have any invalid #'s. */ 2496d756449SSean Bruno p = xbe->xbe_interpreter; 250*1024ef27SKyle Evans interp_offset = 0; 251*1024ef27SKyle Evans argv0_cnt = 0; 252*1024ef27SKyle Evans while ((p = strchr(p, '#')) != NULL) { 2536d756449SSean Bruno p++; 2546d756449SSean Bruno switch(*p) { 2556d756449SSean Bruno case ISM_POUND: 2566d756449SSean Bruno /* "##" */ 2576d756449SSean Bruno p++; 258*1024ef27SKyle Evans interp_offset--; 2596d756449SSean Bruno break; 2606d756449SSean Bruno case ISM_OLD_ARGV0: 2616d756449SSean Bruno /* "#a" */ 2626d756449SSean Bruno p++; 263*1024ef27SKyle Evans argv0_cnt++; 2646d756449SSean Bruno break; 2656d756449SSean Bruno case 0: 2666d756449SSean Bruno default: 2676d756449SSean Bruno /* Anything besides the above is invalid. */ 2686d756449SSean Bruno return (EINVAL); 2696d756449SSean Bruno } 2706d756449SSean Bruno } 2716d756449SSean Bruno 2722192cd12SKyle Evans INTERP_LIST_WLOCK(); 273280b7169SSean Bruno if (imgact_binmisc_find_entry(xbe->xbe_name) != NULL) { 2742192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 275280b7169SSean Bruno return (EEXIST); 276280b7169SSean Bruno } 277280b7169SSean Bruno 2785f98711dSSean Bruno /* Preallocate a new entry. */ 279*1024ef27SKyle Evans ibe = imgact_binmisc_new_entry(xbe, interp_offset, argv0_cnt); 2806d756449SSean Bruno 2816d756449SSean Bruno SLIST_INSERT_HEAD(&interpreter_list, ibe, link); 2826d756449SSean Bruno interp_list_entry_count++; 2832192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 2846d756449SSean Bruno 2856d756449SSean Bruno return (0); 2866d756449SSean Bruno } 2876d756449SSean Bruno 2886d756449SSean Bruno /* 2896d756449SSean Bruno * Remove the interpreter in the list with the given name. Return ENOENT 2906d756449SSean Bruno * if not found. 2916d756449SSean Bruno */ 2926d756449SSean Bruno static int 2936d756449SSean Bruno imgact_binmisc_remove_entry(char *name) 2946d756449SSean Bruno { 2956d756449SSean Bruno imgact_binmisc_entry_t *ibe; 2966d756449SSean Bruno 2972192cd12SKyle Evans INTERP_LIST_WLOCK(); 2986d756449SSean Bruno if ((ibe = imgact_binmisc_find_entry(name)) == NULL) { 2992192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3006d756449SSean Bruno return (ENOENT); 3016d756449SSean Bruno } 3026d756449SSean Bruno SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry, link); 3036d756449SSean Bruno interp_list_entry_count--; 3042192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3056d756449SSean Bruno 3066d756449SSean Bruno imgact_binmisc_destroy_entry(ibe); 3076d756449SSean Bruno 3086d756449SSean Bruno return (0); 3096d756449SSean Bruno } 3106d756449SSean Bruno 3116d756449SSean Bruno /* 3126d756449SSean Bruno * Disable the interpreter in the list with the given name. Return ENOENT 3136d756449SSean Bruno * if not found. 3146d756449SSean Bruno */ 3156d756449SSean Bruno static int 3166d756449SSean Bruno imgact_binmisc_disable_entry(char *name) 3176d756449SSean Bruno { 3186d756449SSean Bruno imgact_binmisc_entry_t *ibe; 3196d756449SSean Bruno 3202192cd12SKyle Evans INTERP_LIST_WLOCK(); 3216d756449SSean Bruno if ((ibe = imgact_binmisc_find_entry(name)) == NULL) { 3222192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3236d756449SSean Bruno return (ENOENT); 3246d756449SSean Bruno } 3256d756449SSean Bruno 3264e83b32aSSean Bruno ibe->ibe_flags &= ~IBF_ENABLED; 3272192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3286d756449SSean Bruno 3296d756449SSean Bruno return (0); 3306d756449SSean Bruno } 3316d756449SSean Bruno 3326d756449SSean Bruno /* 3336d756449SSean Bruno * Enable the interpreter in the list with the given name. Return ENOENT 3346d756449SSean Bruno * if not found. 3356d756449SSean Bruno */ 3366d756449SSean Bruno static int 3376d756449SSean Bruno imgact_binmisc_enable_entry(char *name) 3386d756449SSean Bruno { 3396d756449SSean Bruno imgact_binmisc_entry_t *ibe; 3406d756449SSean Bruno 3412192cd12SKyle Evans INTERP_LIST_WLOCK(); 3426d756449SSean Bruno if ((ibe = imgact_binmisc_find_entry(name)) == NULL) { 3432192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3446d756449SSean Bruno return (ENOENT); 3456d756449SSean Bruno } 3466d756449SSean Bruno 3474e83b32aSSean Bruno ibe->ibe_flags |= IBF_ENABLED; 3482192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 3496d756449SSean Bruno 3506d756449SSean Bruno return (0); 3516d756449SSean Bruno } 3526d756449SSean Bruno 3536d756449SSean Bruno static int 3546d756449SSean Bruno imgact_binmisc_populate_xbe(ximgact_binmisc_entry_t *xbe, 3556d756449SSean Bruno imgact_binmisc_entry_t *ibe) 3566d756449SSean Bruno { 3576d756449SSean Bruno uint32_t i; 3586d756449SSean Bruno 3592192cd12SKyle Evans INTERP_LIST_ASSERT_LOCKED(); 3605f98711dSSean Bruno memset(xbe, 0, sizeof(*xbe)); 3616d756449SSean Bruno strlcpy(xbe->xbe_name, ibe->ibe_name, IBE_NAME_MAX); 3626d756449SSean Bruno 3636d756449SSean Bruno /* Copy interpreter string. Replace NULL breaks with space. */ 3646d756449SSean Bruno memcpy(xbe->xbe_interpreter, ibe->ibe_interpreter, 3656d756449SSean Bruno ibe->ibe_interp_length); 3666d756449SSean Bruno for(i = 0; i < (ibe->ibe_interp_length - 1); i++) 3676d756449SSean Bruno if (xbe->xbe_interpreter[i] == '\0') 3686d756449SSean Bruno xbe->xbe_interpreter[i] = ' '; 3696d756449SSean Bruno 3706d756449SSean Bruno memcpy(xbe->xbe_magic, ibe->ibe_magic, ibe->ibe_msize); 3716d756449SSean Bruno memcpy(xbe->xbe_mask, ibe->ibe_mask, ibe->ibe_msize); 3726d756449SSean Bruno xbe->xbe_version = IBE_VERSION; 3736d756449SSean Bruno xbe->xbe_flags = ibe->ibe_flags; 3746d756449SSean Bruno xbe->xbe_moffset = ibe->ibe_moffset; 3756d756449SSean Bruno xbe->xbe_msize = ibe->ibe_msize; 3766d756449SSean Bruno 3776d756449SSean Bruno return (0); 3786d756449SSean Bruno } 3796d756449SSean Bruno 3806d756449SSean Bruno /* 3816d756449SSean Bruno * Retrieve the interpreter with the give name and populate the 3826d756449SSean Bruno * ximgact_binmisc_entry structure. Return ENOENT if not found. 3836d756449SSean Bruno */ 3846d756449SSean Bruno static int 3856d756449SSean Bruno imgact_binmisc_lookup_entry(char *name, ximgact_binmisc_entry_t *xbe) 3866d756449SSean Bruno { 3876d756449SSean Bruno imgact_binmisc_entry_t *ibe; 3886d756449SSean Bruno int error = 0; 3896d756449SSean Bruno 3902192cd12SKyle Evans INTERP_LIST_RLOCK(); 3916d756449SSean Bruno if ((ibe = imgact_binmisc_find_entry(name)) == NULL) { 3922192cd12SKyle Evans INTERP_LIST_RUNLOCK(); 3936d756449SSean Bruno return (ENOENT); 3946d756449SSean Bruno } 3956d756449SSean Bruno 3966d756449SSean Bruno error = imgact_binmisc_populate_xbe(xbe, ibe); 3972192cd12SKyle Evans INTERP_LIST_RUNLOCK(); 3986d756449SSean Bruno 3996d756449SSean Bruno return (error); 4006d756449SSean Bruno } 4016d756449SSean Bruno 4026d756449SSean Bruno /* 4036d756449SSean Bruno * Get a snapshot of all the interpreter entries in the list. 4046d756449SSean Bruno */ 4056d756449SSean Bruno static int 4066d756449SSean Bruno imgact_binmisc_get_all_entries(struct sysctl_req *req) 4076d756449SSean Bruno { 4086d756449SSean Bruno ximgact_binmisc_entry_t *xbe, *xbep; 4096d756449SSean Bruno imgact_binmisc_entry_t *ibe; 4106d756449SSean Bruno int error = 0, count; 4116d756449SSean Bruno 4122192cd12SKyle Evans INTERP_LIST_RLOCK(); 4136d756449SSean Bruno count = interp_list_entry_count; 414e0ae213fSSean Bruno xbe = malloc(sizeof(*xbe) * count, M_BINMISC, M_WAITOK|M_ZERO); 4156d756449SSean Bruno 4166d756449SSean Bruno xbep = xbe; 4176d756449SSean Bruno SLIST_FOREACH(ibe, &interpreter_list, link) { 4186d756449SSean Bruno error = imgact_binmisc_populate_xbe(xbep++, ibe); 4196d756449SSean Bruno if (error) 4206d756449SSean Bruno break; 4216d756449SSean Bruno } 4222192cd12SKyle Evans INTERP_LIST_RUNLOCK(); 4236d756449SSean Bruno 4246d756449SSean Bruno if (!error) 4256d756449SSean Bruno error = SYSCTL_OUT(req, xbe, sizeof(*xbe) * count); 4266d756449SSean Bruno 4276d756449SSean Bruno free(xbe, M_BINMISC); 4286d756449SSean Bruno return (error); 4296d756449SSean Bruno } 4306d756449SSean Bruno 4316d756449SSean Bruno /* 4326d756449SSean Bruno * sysctl() handler for munipulating interpretor table. 4336d756449SSean Bruno * Not MP safe (locked by sysctl). 4346d756449SSean Bruno */ 4356d756449SSean Bruno static int 4366d756449SSean Bruno sysctl_kern_binmisc(SYSCTL_HANDLER_ARGS) 4376d756449SSean Bruno { 4386d756449SSean Bruno ximgact_binmisc_entry_t xbe; 4396d756449SSean Bruno int error = 0; 4406d756449SSean Bruno 4416d756449SSean Bruno switch(arg2) { 4426d756449SSean Bruno case IBC_ADD: 4436d756449SSean Bruno /* Add an entry. Limited to IBE_MAX_ENTRIES. */ 4446d756449SSean Bruno error = SYSCTL_IN(req, &xbe, sizeof(xbe)); 4456d756449SSean Bruno if (error) 4466d756449SSean Bruno return (error); 4476d756449SSean Bruno if (IBE_VERSION != xbe.xbe_version) 4486d756449SSean Bruno return (EINVAL); 4497d3ed977SKyle Evans if ((xbe.xbe_flags & ~IBF_VALID_UFLAGS) != 0) 4507d3ed977SKyle Evans return (EINVAL); 4516d756449SSean Bruno if (interp_list_entry_count == IBE_MAX_ENTRIES) 4526d756449SSean Bruno return (ENOSPC); 4536d756449SSean Bruno error = imgact_binmisc_add_entry(&xbe); 4546d756449SSean Bruno break; 4556d756449SSean Bruno 4566d756449SSean Bruno case IBC_REMOVE: 4576d756449SSean Bruno /* Remove an entry. */ 4586d756449SSean Bruno error = SYSCTL_IN(req, &xbe, sizeof(xbe)); 4596d756449SSean Bruno if (error) 4606d756449SSean Bruno return (error); 4616d756449SSean Bruno if (IBE_VERSION != xbe.xbe_version) 4626d756449SSean Bruno return (EINVAL); 4636d756449SSean Bruno error = imgact_binmisc_remove_entry(xbe.xbe_name); 4646d756449SSean Bruno break; 4656d756449SSean Bruno 4666d756449SSean Bruno case IBC_DISABLE: 4676d756449SSean Bruno /* Disable an entry. */ 4686d756449SSean Bruno error = SYSCTL_IN(req, &xbe, sizeof(xbe)); 4696d756449SSean Bruno if (error) 4706d756449SSean Bruno return (error); 4716d756449SSean Bruno if (IBE_VERSION != xbe.xbe_version) 4726d756449SSean Bruno return (EINVAL); 4736d756449SSean Bruno error = imgact_binmisc_disable_entry(xbe.xbe_name); 4746d756449SSean Bruno break; 4756d756449SSean Bruno 4766d756449SSean Bruno case IBC_ENABLE: 4776d756449SSean Bruno /* Enable an entry. */ 4786d756449SSean Bruno error = SYSCTL_IN(req, &xbe, sizeof(xbe)); 4796d756449SSean Bruno if (error) 4806d756449SSean Bruno return (error); 4816d756449SSean Bruno if (IBE_VERSION != xbe.xbe_version) 4826d756449SSean Bruno return (EINVAL); 4836d756449SSean Bruno error = imgact_binmisc_enable_entry(xbe.xbe_name); 4846d756449SSean Bruno break; 4856d756449SSean Bruno 4866d756449SSean Bruno case IBC_LOOKUP: 4876d756449SSean Bruno /* Lookup an entry. */ 4886d756449SSean Bruno error = SYSCTL_IN(req, &xbe, sizeof(xbe)); 4896d756449SSean Bruno if (error) 4906d756449SSean Bruno return (error); 4916d756449SSean Bruno if (IBE_VERSION != xbe.xbe_version) 4926d756449SSean Bruno return (EINVAL); 4936d756449SSean Bruno error = imgact_binmisc_lookup_entry(xbe.xbe_name, &xbe); 4946d756449SSean Bruno if (!error) 4956d756449SSean Bruno error = SYSCTL_OUT(req, &xbe, sizeof(xbe)); 4966d756449SSean Bruno break; 4976d756449SSean Bruno 4986d756449SSean Bruno case IBC_LIST: 4996d756449SSean Bruno /* Return a snapshot of the interpretor list. */ 5006d756449SSean Bruno 5016d756449SSean Bruno if (!req->oldptr) { 5026d756449SSean Bruno /* No pointer then just return the list size. */ 5036d756449SSean Bruno error = SYSCTL_OUT(req, 0, interp_list_entry_count * 5046d756449SSean Bruno sizeof(ximgact_binmisc_entry_t)); 5056d756449SSean Bruno return (error); 5066d756449SSean Bruno } else 5076d756449SSean Bruno if (!req->oldlen) 5086d756449SSean Bruno return (EINVAL); 5096d756449SSean Bruno 5106d756449SSean Bruno error = imgact_binmisc_get_all_entries(req); 5116d756449SSean Bruno break; 5126d756449SSean Bruno 5136d756449SSean Bruno default: 5146d756449SSean Bruno return (EINVAL); 5156d756449SSean Bruno } 5166d756449SSean Bruno 5176d756449SSean Bruno return (error); 5186d756449SSean Bruno } 5196d756449SSean Bruno 5207029da5cSPawel Biernacki SYSCTL_NODE(_kern, OID_AUTO, binmisc, CTLFLAG_RW | CTLFLAG_MPSAFE, 0, 5216d756449SSean Bruno "Image activator for miscellaneous binaries"); 5226d756449SSean Bruno 5236d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, add, 5246d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ADD, 5256d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5266d756449SSean Bruno "Add an activator entry"); 5276d756449SSean Bruno 5286d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, remove, 5296d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_REMOVE, 5306d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5316d756449SSean Bruno "Remove an activator entry"); 5326d756449SSean Bruno 5336d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, disable, 5346d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_DISABLE, 5356d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5366d756449SSean Bruno "Disable an activator entry"); 5376d756449SSean Bruno 5386d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, enable, 5396d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ENABLE, 5406d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5416d756449SSean Bruno "Enable an activator entry"); 5426d756449SSean Bruno 5436d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, lookup, 5446d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RW|CTLFLAG_ANYBODY, NULL, IBC_LOOKUP, 5456d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5466d756449SSean Bruno "Lookup an activator entry"); 5476d756449SSean Bruno 5486d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, list, 5496d756449SSean Bruno CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RD|CTLFLAG_ANYBODY, NULL, IBC_LIST, 5506d756449SSean Bruno sysctl_kern_binmisc, "S,ximgact_binmisc_entry", 5516d756449SSean Bruno "Get snapshot of all the activator entries"); 5526d756449SSean Bruno 5536d756449SSean Bruno static imgact_binmisc_entry_t * 5546d756449SSean Bruno imgact_binmisc_find_interpreter(const char *image_header) 5556d756449SSean Bruno { 5566d756449SSean Bruno imgact_binmisc_entry_t *ibe; 5576d756449SSean Bruno const char *p; 5586d756449SSean Bruno int i; 5596d756449SSean Bruno size_t sz; 5606d756449SSean Bruno 5612192cd12SKyle Evans INTERP_LIST_ASSERT_LOCKED(); 5626d756449SSean Bruno 5636d756449SSean Bruno SLIST_FOREACH(ibe, &interpreter_list, link) { 5646d756449SSean Bruno if (!(IBF_ENABLED & ibe->ibe_flags)) 5656d756449SSean Bruno continue; 5666d756449SSean Bruno 5676d756449SSean Bruno p = image_header + ibe->ibe_moffset; 5686d756449SSean Bruno sz = ibe->ibe_msize; 5696d756449SSean Bruno if (IBF_USE_MASK & ibe->ibe_flags) { 5706d756449SSean Bruno /* Compare using mask. */ 5716d756449SSean Bruno for (i = 0; i < sz; i++) 5726d756449SSean Bruno if ((*p++ ^ ibe->ibe_magic[i]) & 5736d756449SSean Bruno ibe->ibe_mask[i]) 5746d756449SSean Bruno break; 5756d756449SSean Bruno } else { 5766d756449SSean Bruno for (i = 0; i < sz; i++) 5776d756449SSean Bruno if (*p++ ^ ibe->ibe_magic[i]) 5786d756449SSean Bruno break; 5796d756449SSean Bruno } 5806d756449SSean Bruno if (i == ibe->ibe_msize) 5816d756449SSean Bruno return (ibe); 5826d756449SSean Bruno } 5836d756449SSean Bruno return (NULL); 5846d756449SSean Bruno } 5856d756449SSean Bruno 586945afa7cSSean Bruno static int 5876d756449SSean Bruno imgact_binmisc_exec(struct image_params *imgp) 5886d756449SSean Bruno { 5896d756449SSean Bruno const char *image_header = imgp->image_header; 5906d756449SSean Bruno const char *fname = NULL; 5916d756449SSean Bruno int error = 0; 592*1024ef27SKyle Evans #ifdef INVARIANTS 593*1024ef27SKyle Evans int argv0_cnt = 0; 594*1024ef27SKyle Evans #endif 595*1024ef27SKyle Evans size_t namelen, offset; 5966d756449SSean Bruno imgact_binmisc_entry_t *ibe; 5976d756449SSean Bruno struct sbuf *sname; 5986d756449SSean Bruno char *s, *d; 5996d756449SSean Bruno 60080083216SKyle Evans sname = NULL; 601*1024ef27SKyle Evans namelen = 0; 6026d756449SSean Bruno /* Do we have an interpreter for the given image header? */ 6032192cd12SKyle Evans INTERP_LIST_RLOCK(); 6046d756449SSean Bruno if ((ibe = imgact_binmisc_find_interpreter(image_header)) == NULL) { 60580083216SKyle Evans error = -1; 60680083216SKyle Evans goto done; 6076d756449SSean Bruno } 6086d756449SSean Bruno 6096d756449SSean Bruno /* No interpreter nesting allowed. */ 61065f20a89SSean Bruno if (imgp->interpreted & IMGACT_BINMISC) { 61180083216SKyle Evans error = ENOEXEC; 61280083216SKyle Evans goto done; 6136d756449SSean Bruno } 6146d756449SSean Bruno 61565f20a89SSean Bruno imgp->interpreted |= IMGACT_BINMISC; 6166d756449SSean Bruno 617*1024ef27SKyle Evans /* 618*1024ef27SKyle Evans * Don't bother with the overhead of putting fname together if we're not 619*1024ef27SKyle Evans * using #a. 620*1024ef27SKyle Evans */ 621*1024ef27SKyle Evans if (ibe->ibe_argv0_cnt != 0) { 6226d756449SSean Bruno if (imgp->args->fname != NULL) { 6236d756449SSean Bruno fname = imgp->args->fname; 6246d756449SSean Bruno } else { 6256d756449SSean Bruno /* Use the fdescfs(5) path for fexecve(2). */ 6266d756449SSean Bruno sname = sbuf_new_auto(); 6276d756449SSean Bruno sbuf_printf(sname, "/dev/fd/%d", imgp->args->fd); 6286d756449SSean Bruno sbuf_finish(sname); 6296d756449SSean Bruno fname = sbuf_data(sname); 6306d756449SSean Bruno } 6316d756449SSean Bruno 632*1024ef27SKyle Evans namelen = strlen(fname); 633*1024ef27SKyle Evans } 634*1024ef27SKyle Evans 6356d756449SSean Bruno /* 6366d756449SSean Bruno * We need to "push" the interpreter in the arg[] list. To do this, 6376d756449SSean Bruno * we first shift all the other values in the `begin_argv' area to 6386d756449SSean Bruno * provide the exact amount of room for the values added. Set up 6396d756449SSean Bruno * `offset' as the number of bytes to be added to the `begin_argv' 640*1024ef27SKyle Evans * area. ibe_interp_offset is the fixed offset from macros present in 641*1024ef27SKyle Evans * the interpreter string. 6426d756449SSean Bruno */ 643*1024ef27SKyle Evans offset = ibe->ibe_interp_length + ibe->ibe_interp_offset; 6446d756449SSean Bruno 645*1024ef27SKyle Evans /* Variable offset to be added from macros to the interpreter string. */ 646*1024ef27SKyle Evans MPASS(ibe->ibe_argv0_cnt == 0 || namelen > 0); 647*1024ef27SKyle Evans offset += ibe->ibe_argv0_cnt * (namelen - 2); 6486d756449SSean Bruno 649f373437aSBrooks Davis /* Make room for the interpreter */ 650f373437aSBrooks Davis error = exec_args_adjust_args(imgp->args, 0, offset); 651f373437aSBrooks Davis if (error != 0) { 6526d756449SSean Bruno goto done; 6536d756449SSean Bruno } 6546d756449SSean Bruno 6556d756449SSean Bruno /* Add the new argument(s) in the count. */ 6566d756449SSean Bruno imgp->args->argc += ibe->ibe_interp_argcnt; 6576d756449SSean Bruno 6586d756449SSean Bruno /* 6596d756449SSean Bruno * The original arg[] list has been shifted appropriately. Copy in 6606d756449SSean Bruno * the interpreter path. 6616d756449SSean Bruno */ 6626d756449SSean Bruno s = ibe->ibe_interpreter; 6636d756449SSean Bruno d = imgp->args->begin_argv; 6646d756449SSean Bruno while(*s != '\0') { 6656d756449SSean Bruno switch (*s) { 6666d756449SSean Bruno case '#': 6676d756449SSean Bruno /* Handle "#" in interpreter string. */ 6686d756449SSean Bruno s++; 6696d756449SSean Bruno switch(*s) { 6706d756449SSean Bruno case ISM_POUND: 6716d756449SSean Bruno /* "##": Replace with a single '#' */ 6726d756449SSean Bruno *d++ = '#'; 6736d756449SSean Bruno break; 6746d756449SSean Bruno case ISM_OLD_ARGV0: 6756d756449SSean Bruno /* "#a": Replace with old arg0 (fname). */ 676*1024ef27SKyle Evans MPASS(ibe->ibe_argv0_cnt >= ++argv0_cnt); 677*1024ef27SKyle Evans memcpy(d, fname, namelen); 678*1024ef27SKyle Evans d += namelen; 6796d756449SSean Bruno break; 6806d756449SSean Bruno default: 681*1024ef27SKyle Evans __assert_unreachable(); 6826d756449SSean Bruno } 6836d756449SSean Bruno break; 6846d756449SSean Bruno case ' ': 685e3043798SPedro F. Giffuni /* Replace space with NUL to separate arguments. */ 6866d756449SSean Bruno *d++ = '\0'; 6876d756449SSean Bruno break; 6886d756449SSean Bruno default: 6896d756449SSean Bruno *d++ = *s; 6906d756449SSean Bruno break; 6916d756449SSean Bruno } 6926d756449SSean Bruno s++; 6936d756449SSean Bruno } 6946d756449SSean Bruno *d = '\0'; 6956d756449SSean Bruno 696*1024ef27SKyle Evans /* Catch ibe->ibe_argv0_cnt counting more #a than we did. */ 697*1024ef27SKyle Evans MPASS(ibe->ibe_argv0_cnt == argv0_cnt); 6986d756449SSean Bruno imgp->interpreter_name = imgp->args->begin_argv; 6996d756449SSean Bruno 7006d756449SSean Bruno done: 7012192cd12SKyle Evans INTERP_LIST_RUNLOCK(); 7026d756449SSean Bruno if (sname) 7036d756449SSean Bruno sbuf_delete(sname); 7046d756449SSean Bruno return (error); 7056d756449SSean Bruno } 7066d756449SSean Bruno 7076d756449SSean Bruno static void 7086d756449SSean Bruno imgact_binmisc_init(void *arg) 7096d756449SSean Bruno { 7106d756449SSean Bruno 7112192cd12SKyle Evans INTERP_LIST_LOCK_INIT(); 7126d756449SSean Bruno } 7136d756449SSean Bruno 7146d756449SSean Bruno static void 7156d756449SSean Bruno imgact_binmisc_fini(void *arg) 7166d756449SSean Bruno { 7176d756449SSean Bruno imgact_binmisc_entry_t *ibe, *ibe_tmp; 7186d756449SSean Bruno 7196d756449SSean Bruno /* Free all the interpreters. */ 7202192cd12SKyle Evans INTERP_LIST_WLOCK(); 7216d756449SSean Bruno SLIST_FOREACH_SAFE(ibe, &interpreter_list, link, ibe_tmp) { 7226d756449SSean Bruno SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry, 7236d756449SSean Bruno link); 7246d756449SSean Bruno imgact_binmisc_destroy_entry(ibe); 7256d756449SSean Bruno } 7262192cd12SKyle Evans INTERP_LIST_WUNLOCK(); 7276d756449SSean Bruno 7282192cd12SKyle Evans INTERP_LIST_LOCK_DESTROY(); 7296d756449SSean Bruno } 7306d756449SSean Bruno 731891cf3edSEd Maste SYSINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_init, 732891cf3edSEd Maste NULL); 733891cf3edSEd Maste SYSUNINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_fini, 734891cf3edSEd Maste NULL); 7356d756449SSean Bruno 7366d756449SSean Bruno /* 7376d756449SSean Bruno * Tell kern_execve.c about it, with a little help from the linker. 7386d756449SSean Bruno */ 739b7feabf9SEd Maste static struct execsw imgact_binmisc_execsw = { 740b7feabf9SEd Maste .ex_imgact = imgact_binmisc_exec, 741b7feabf9SEd Maste .ex_name = KMOD_NAME 742b7feabf9SEd Maste }; 7436d756449SSean Bruno EXEC_SET(imgact_binmisc, imgact_binmisc_execsw); 744